← bakkuPrivacy Policy
Last updated August 10, 2026
bakku ("bakku", "we", "us") operates Rebooking Catcher, a tool that helps service businesses identify clients who are overdue for a repeat visit and send them a nudge to rebook. This policy explains what data we collect, how we use it, and your rights — for both business owners who use bakku, and the clients of those businesses whose contact info a business owner uploads.
This is a plain-language summary of our practices, not a substitute for legal advice. If you have specific compliance requirements, please consult your own counsel.
1. Who this applies to
"Business", "you", "your account" — the service-business owner who signs up for bakku. "End clients" / "your clients" — the individual people (customers, patients, students) whose name, contact details, and visit history you import into bakku so it can detect who's overdue and send a nudge on your behalf.
bakku acts as:
- Data controller for your own account information (email, business profile, billing details).
- Data processor for your end clients' personal data — you remain the data controller for that data. You're responsible for having a lawful basis to hold and use it, and for making sure everyone on your list is an existing client of yours, never a purchased or scraped list.
2. What we collect
From you, the business owner:
- Email address (used for magic-link sign-in — we never see or store a password).
- Business name, niche, visit-cycle settings, and currency.
- Billing information, handled directly by Stripe — we store only your Stripe customer/subscription IDs and plan status, never your card details.
From the CSV you import, about your end clients:
- Name, email address, last visit date.
- Optionally, a per-client visit value or cycle override.
Automatically:
- Standard server logs (IP address, timestamps) for security and abuse prevention.
- A session cookie to keep you signed in — no tracking or advertising cookies.
3. How we use it
- To detect which of your clients are overdue and generate your dashboard.
- To send the nudge emails on your behalf, under your business's name, to the clients you've imported.
- To process your subscription payments.
- To operate, secure, and improve the service.
We do not sell your data or your end clients' data to anyone, and we don't use your end clients' contact information for anything beyond the nudges you've configured.
4. Who we share it with (sub-processors)
We use the following providers to run bakku. Each receives only the minimum data needed to do its job:
- Supabase — database hosting and authentication.
- Resend — sends the nudge emails on our behalf.
- Stripe — processes subscription payments.
- Vercel — hosts the application.
5. Data retention
- We keep your account and client data for as long as your account is active.
- If you cancel, your data is retained briefly in case you reactivate, then deleted.
- You — or your end clients, via the one-click unsubscribe link in every nudge email — can request deletion at any time by contacting us.
6. Your rights (and your end clients' rights)
If you or your end clients are in the EU/UK, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion ("right to be forgotten").
- Object to or restrict processing.
- Data portability.
- Lodge a complaint with your local data protection authority.
Every nudge email includes a one-click unsubscribe link that immediately and automatically stops future emails to that person.
7. Security
We use encrypted connections (TLS) for all data in transit, encrypted storage at rest via our hosting providers, and access controls limiting who can see your data.
8. Changes to this policy
We'll post updates here and, for material changes, notify account holders by email.
9. Contact
Questions about this policy, or a request regarding your data: hello@bakku.co